50b0c0c1ea690326b4b18b2dafc8a60d39425ab32a436d60f5eabd720dd890c0

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-03 05:34:56
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • bcdedit.exe
  • procexp.exe
  • procmon.exe
  • sc.exe
  • wireshark.exe
Contains references to debugging or reversing tools:
  • ida.exe
  • ida64.exe
  • idaq.exe
  • idaq64.exe
  • ollydbg.exe
  • windbg.exe
  • x32dbg.exe
  • x64dbg.exe
Contains references to security software:
  • rshell.exe
Looks for VMWare presence:
  • VMware
  • hgfs.sys
  • mhgfs.sys
  • vmmouse
  • vmware
Looks for Sandboxie presence:
  • sbiedll.dll
Looks for VirtualBox presence:
  • VBoxGuest
  • VBoxMouse
  • VBoxTray
  • \\.\pipe\VBoxMiniRdDN
  • \\.\pipe\VBoxTrayIPC
  • vboxhook.dll
  • vboxsf
Looks for Qemu presence:
  • qemu
May have dropper capabilities:
  • %TEMP%
  • CurrentControlSet\Services
Accesses the WMI:
  • ROOT\Microsoft
Miscellaneous malware strings:
  • Virus
  • exploit
  • virus
Contains domain names:
  • download.microsoft.com
  • go.microsoft.com
  • https://aka.ms
  • https://download.microsoft.com
  • https://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxwebsetup.exe
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/p/?LinkId
  • microsoft.com
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. Functions which can be used for anti-debugging purposes:
  • FindWindowA
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegDeleteKeyA
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegSetValueExW
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCreateKeyExW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
  • ShellExecuteA
  • CreateProcessW
  • CreateProcessA
Uses Microsoft's cryptographic API:
  • CryptProtectData
  • CryptUnprotectData
Can create temporary files:
  • GetTempPathW
  • CreateFileW
  • CreateFileA
  • GetTempPathA
Has Internet access capabilities:
  • WinHttpQueryOption
  • WinHttpQueryDataAvailable
  • WinHttpQueryHeaders
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpSetTimeouts
  • WinHttpSetOption
  • WinHttpReadData
  • WinHttpConnect
  • WinHttpCloseHandle
  • WinHttpCrackUrl
  • WinHttpOpen
  • WinHttpOpenRequest
  • URLDownloadToFileW
  • URLDownloadToFileA
Functions related to the privilege level:
  • CheckTokenMembership
Enumerates local disk drives:
  • GetVolumeInformationA
Manipulates other processes:
  • OpenProcess
  • Process32NextW
  • Process32FirstW
Can take screenshots:
  • FindWindowA
  • CreateCompatibleDC
  • BitBlt
Suspicious The file contains overlay data. 1929 bytes of data starting at offset 0x9a000.
The overlay data has an entropy of 7.90909 and is possibly compressed or encrypted.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 b12eff2fe99407318be8e54c7c3df6b9 🔍
SHA1 83c011f64d79374ceb380cf12304c933a14b2be7 🔍
SHA256 50b0c0c1ea690326b4b18b2dafc8a60d39425ab32a436d60f5eabd720dd890c0 🔍
SHA3 c887efc39957f1541afde7f586dfc52566641afaffb159b3ba7e6bba19a6c782 🔍
SSDeep 6144:htgSmBaoDMuBTBtjulxjJ73v9Bq4DqauKTGqk0MEQjx5xRBhT8PpN/0t6r0VKrNm:hMfzuJfaKThQN4/rpxoSx7WixkWY 🔍
Imports Hash 97b48a7cd335e0b7242f89e332c2e73e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Sep-03 05:34:56
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x72400
SizeOfInitializedData 0x28a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000006D350 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa0000
SizeOfHeaders 0x400
Checksum 0xa84ed
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 60c1afbca11191773762919602b96ba7 🔍
SHA1 bbb8925b974221426d897bc96639be70308177e6 🔍
SHA256 8a8dc3f02a16bc0a2139ad88eaeb370a549cfa317c013ec8f5e2f0054e316779 🔍
SHA3 761638f8fabf1624b43b37ac5ae3dea1c1e017b47f1ef180f1e7d3231ac5fa88 🔍
VirtualSize 0x72377
VirtualAddress 0x1000
SizeOfRawData 0x72400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50669

.rdata

MD5 7f4e4109f605b933911ea4bd25b46af2 🔍
SHA1 45f29ac5ce0e1329250335d687fa7bd2715cdbc8 🔍
SHA256 877accc86aa05771e11e3ef45e69dd728c3078e37b129846ff2582adb7f5918e 🔍
SHA3 842dac624907c2b1143b78ae1ad36e37441b411c0fd81a5732f45d93398e0512 🔍
VirtualSize 0x22802
VirtualAddress 0x74000
SizeOfRawData 0x22a00
PointerToRawData 0x72800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.94783

.data

MD5 b5af18813324db56a08f61e8945d26fc 🔍
SHA1 f65431959c48ecaab4c4b06451356473f4c56dbb 🔍
SHA256 5b397a94b6cecdc04ec546344df22fb18e04997579c68491e9ff8031841d00e6 🔍
SHA3 81f93a2702bbe6077097859eb3f1417fa476fbee491dcc0d7ff0ba25cf8c712f 🔍
VirtualSize 0x2388
VirtualAddress 0x97000
SizeOfRawData 0x1200
PointerToRawData 0x95200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.47842

.pdata

MD5 7349704bdacce5d06c3190390c291d1e 🔍
SHA1 f116338b14e554abef3d24c163f295e938385b2e 🔍
SHA256 1e60f032ef0ec554259291c4e3f19dc221d1a4fc4e6e53f582bfd8848995533c 🔍
SHA3 5e8aab39df88dcb0577199a30865bf16f5bbdb55ab16ec2887c6e8ef86d70f71 🔍
VirtualSize 0x35e8
VirtualAddress 0x9a000
SizeOfRawData 0x3600
PointerToRawData 0x96400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.82366

.rsrc

MD5 11d1748cae04a0874ae786347f497e43 🔍
SHA1 28cfa775c119f61476622d4c8242c7c126d3868b 🔍
SHA256 d36fe06208624b14661ed5285970e27d4e632a9395c2ee3d5a38823b26e8023a 🔍
SHA3 6dee411fbc4b0c4ada88eb88dbd4fce5b38f70addeaa50ee6ca9f89fc876844d 🔍
VirtualSize 0x1e0
VirtualAddress 0x9e000
SizeOfRawData 0x200
PointerToRawData 0x99a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71377

.reloc

MD5 a31fe9fa934c56d09de44a5e77442f74 🔍
SHA1 dfff0ee07e5f76c2025cb7289923df9d6068d1de 🔍
SHA256 bce7ecac6740b71cde729387b3305ab36ad1d827be307819fda9868599214e88 🔍
SHA3 b6daf3632d579bcfcd0fb332f791d90e759c1c3f629b4c88a919bd8653fd4eda 🔍
VirtualSize 0x26c
VirtualAddress 0x9f000
SizeOfRawData 0x400
PointerToRawData 0x99c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.74893

Imports

WINHTTP.dll WinHttpQueryOption
WinHttpQueryDataAvailable
WinHttpQueryHeaders
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpSetTimeouts
WinHttpSetOption
WinHttpReadData
WinHttpConnect
WinHttpCloseHandle
WinHttpCrackUrl
WinHttpOpen
WinHttpOpenRequest
CRYPT32.dll CryptProtectData
CryptUnprotectData
CertFreeCertificateContext
bcrypt.dll BCryptCreateHash
BCryptHashData
BCryptFinishHash
BCryptDestroyHash
BCryptGetProperty
BCryptSetProperty
BCryptGenerateSymmetricKey
BCryptDecrypt
BCryptDestroyKey
BCryptGenRandom
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
USER32.dll SetCursor
ScreenToClient
LoadCursorW
FindWindowA
MessageBeep
MessageBoxW
TrackMouseEvent
GetMessageW
TranslateMessage
GetCursorPos
SendMessageW
DefWindowProcW
PostQuitMessage
RegisterClassExW
CreateWindowExW
ShowWindow
GetSystemMetrics
UpdateWindow
BeginPaint
EndPaint
SetWindowRgn
InvalidateRect
SetWindowTextA
GetWindowTextA
GetClientRect
DispatchMessageW
GDI32.dll SetTextColor
SetBkColor
DeleteObject
DeleteDC
CreateSolidBrush
CreateRoundRectRgn
CreateFontW
CreateCompatibleDC
CreateCompatibleBitmap
BitBlt
SelectObject
SHELL32.dll ShellExecuteW
ShellExecuteExA
ShellExecuteA
ADVAPI32.dll FreeSid
RegDeleteKeyA
RegQueryValueExA
RegOpenKeyExA
RegSetValueExW
RegQueryValueExW
RegOpenKeyExW
RegCreateKeyExW
RegCloseKey
AllocateAndInitializeSid
CheckTokenMembership
GetUserNameA
ole32.dll CoCreateInstance
CoSetProxyBlanket
CoInitializeEx
CoUninitialize
OLEAUT32.dll VariantClear
VariantInit
gdiplus.dll GdipAddPathArc
GdipAddPathBezier
GdipAddPathEllipse
GdipCloneBrush
GdipDeleteBrush
GdipCreateSolidFill
GdipCreateLineBrush
GdipFillRectangle
GdipCreateLineBrushI
GdipCreatePen1
GdipGetGenericFontFamilySansSerif
GdipDeletePen
GdipClosePathFigure
GdipGetPenWidth
GdipCloneImage
GdipDeletePath
GdipCreateBitmapFromFile
GdipCreateFromHDC
GdipDeleteGraphics
GdipSetSmoothingMode
GdipSetTextRenderingHint
GdipSetInterpolationMode
GdipDrawLine
GdipDrawLineI
GdipDrawEllipse
GdipDrawPath
GdipFillRectangleI
GdipFillPolygon
GdipFillEllipse
GdipFillPath
GdipDrawImageRect
GdipSetClipPath
GdipAddPathLine
GdipCreatePath
GdiplusShutdown
GdiplusStartup
GdipFree
GdipAlloc
GdipDeleteFont
GdipDrawString
GdipCreateStringFormat
GdipDeleteStringFormat
GdipSetStringFormatAlign
GdipDisposeImage
GdipSetStringFormatLineAlign
GdipSaveGraphics
GdipRestoreGraphics
GdipCreateFontFamilyFromName
GdipDeleteFontFamily
GdipCreateFont
KERNEL32.dll GetFileAttributesExW
GetFileAttributesW
FindNextFileW
FindFirstFileExW
FindFirstFileW
FindClose
GetLocaleInfoEx
FormatMessageA
GetCurrentThreadId
Sleep
SleepConditionVariableSRW
GetFinalPathNameByHandleW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
OpenFileMappingW
GetTickCount64
CreateProcessW
GetTempPathW
QueryDosDeviceW
CreateDirectoryW
OpenProcess
Process32NextW
Process32FirstW
GetFullPathNameW
SetFileInformationByHandle
AreFileApisANSI
CopyFileW
InitializeSListHead
MoveFileExW
GetFileInformationByHandle
CreateToolhelp32Snapshot
WaitNamedPipeA
GetModuleFileNameW
VirtualQuery
GetFileInformationByHandleEx
WakeAllConditionVariable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetSystemTimeAsFileTime
VirtualProtect
GetSystemInfo
GlobalMemoryStatusEx
GetThreadContext
GetCurrentThread
QueryPerformanceFrequency
QueryPerformanceCounter
SetLastError
GetLastError
GetFileSize
GetDiskFreeSpaceExA
CreateFileW
GetSystemFirmwareTable
GetVolumeInformationA
CreateFileA
CreateDirectoryA
WideCharToMultiByte
MultiByteToWideChar
GetProcAddress
GetModuleHandleA
GetCurrentProcess
DeleteFileA
GetWindowsDirectoryA
GetSystemDirectoryA
GetTickCount
CreateProcessA
GetExitCodeProcess
PeekNamedPipe
CreatePipe
SetHandleInformation
GetTempPathA
ReadFile
GetComputerNameA
LocalFree
GetModuleHandleW
GetModuleFileNameA
TerminateProcess
ExitProcess
GetCurrentProcessId
WaitForSingleObject
CloseHandle
SetFileAttributesA
GetFileAttributesA
GetEnvironmentVariableA
MSVCP140.dll ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?_Id_cnt@id@locale@std@@0HA
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?uncaught_exceptions@std@@YAHXZ
?_Xbad_function_call@std@@YAXXZ
??Bios_base@std@@QEBA_NXZ
?good@ios_base@std@@QEBA_NXZ
?flags@ios_base@std@@QEBAHXZ
?width@ios_base@std@@QEBA_JXZ
?width@ios_base@std@@QEAA_J_J@Z
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
_Xtime_get_ticks
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?setf@ios_base@std@@QEAAHHH@Z
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAADD@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
?_Xbad_alloc@std@@YAXXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
_Query_perf_counter
_Query_perf_frequency
_Thrd_detach
_Mtx_lock
_Mtx_unlock
_Cnd_do_broadcast_at_thread_exit
?_Throw_Cpp_error@std@@YAXH@Z
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??7ios_base@std@@QEBA_NXZ
urlmon.dll URLDownloadToFileW
URLDownloadToFileA
VCRUNTIME140.dll __current_exception
__C_specific_handler
strstr
memset
memmove
memcpy
memcmp
__current_exception_context
_CxxThrowException
__std_exception_destroy
__std_exception_copy
__std_terminate
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll _c_exit
_cexit
_get_narrow_winmain_command_line
_seh_filter_exe
_exit
_initterm_e
_register_thread_local_exe_atexit_callback
_crt_atexit
_invoke_watson
_configure_narrow_argv
_initialize_narrow_environment
_errno
_initterm
exit
_beginthreadex
abort
terminate
_register_onexit_function
_set_app_type
_initialize_onexit_table
api-ms-win-crt-string-l1-1-0.dll _wcsicmp
tolower
wcslen
wcsncmp
strlen
toupper
_stricmp
isspace
api-ms-win-crt-heap-l1-1-0.dll malloc
_callnewh
free
_set_new_mode
api-ms-win-crt-convert-l1-1-0.dll strtoul
strtoll
strtol
api-ms-win-crt-stdio-l1-1-0.dll fsetpos
_fseeki64
fwrite
setvbuf
fread
fgetpos
fgetc
fflush
fclose
_get_stream_buffer_pointers
ungetc
__p__commode
__stdio_common_vsprintf
_set_fmode
__stdio_common_vswprintf_s
fputc
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-time-l1-1-0.dll _time64
_localtime64_s
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
___lc_codepage_func
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Oct-10 03:03:35
Version 0.0
SizeofData 964
AddressOfRawData 0x87c50
PointerToRawData 0x86450

UNKNOWN

Characteristics 0
TimeDateStamp 2026-Oct-10 03:03:35
Version 0.0
SizeofData 4
AddressOfRawData 0x88014
PointerToRawData 0x86814

TLS Callbacks

StartAddressOfRawData 0x140088040
EndAddressOfRawData 0x14008a110
AddressOfIndex 0x140098dd8
AddressOfCallbacks 0x140074e18
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140097600
GuardCFCheckFunctionPointer 5369187592
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xcce43b23
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 34
Imports (35207) 6
C objects (33145) 1
Imports (33145) 25
Total imports 416
C++ objects (35228) 8
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.